Corma Raises $60M to Build AI for the Other Side of the Cyber War
As AI-powered attacks become faster and more autonomous, Corma wants to put an AI workforce on the defensive side
CybersecurityAI startup Corma has raised $60 million to build what it describes as a new kind of defensive AI: a foundation model and AI agents designed specifically to detect, investigate and respond to threats across enterprise environments.
The seed round was led by Sequoia Capital, with participation from Khosla Ventures and Coatue. Corma was founded in 2025 by CEO Alon Pluda and is headquartered in Tel Aviv and San Francisco, bringing together AI researchers from Google and DeepMind with cybersecurity specialists, including veterans of Israel’s 8200 Unit.
The company is tackling a growing problem in cybersecurity: AI is becoming remarkably good at helping attackers, but that does not mean the same models are equally good at defending organizations
According to Corma, models such as OpenAI’s GPT, Anthropic’s Claude and Google’s Gemini can write code, find software vulnerabilities and operate tools across multiple steps. In the hands of an attacker, that means they can help identify a weakness, develop an exploit and carry out parts of an attack with little human intervention.
Defense is much messier. A security team has to monitor an entire organization, sorting through huge volumes of logs, alerts, network traffic and other data to find small clues that may only become meaningful when connected over time. It also has to make thousands of decisions while an attack is unfolding.
Corma tested this difference in hundreds of simulations using enterprise environments modeled on Fortune 500 companies. Leading AI models were asked first to attack the environments and then to defend against those same attacks. They succeeded as attackers 88% of the time, but detected only 12% of the attacks when placed on defense.
Corma is building a foundation model specifically for this defensive work. Its AI agents are designed to learn an organization’s environment, investigate threats and perform tasks across multiple security functions. The company says its technology is already deployed at Fortune 100 and Fortune 500 organizations, where early deployments have cut threat-response times by more than 94%.
“The race to general intelligence in cybersecurity has already begun, and the attackers have a significant head start,” Pluda said.